Vulnerability record · CVE-2010-0240 · published 10 February 2010
CVE-2010-0240: Windows TCP/IP ESP-over-UDP Fragmentation Code Execution
Microsoft · Windows Server 2008
Microsoft Windows Vista and Server 2008 fail to properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets when a custom network driver is used. Crafted packets can trigger memory corruption that permits remote code execution. The flaw is serious because it is network-reachable and requires no authentication.
Description
The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when a custom network driver is used, does not properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "Header MDL Fragmentation Vulnerability."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication and full code execution impact, plus a high EPSS percentile, makes this a top remediation priority despite no KEV listing.
What it is
Microsoft Windows Vista and Server 2008 fail to properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets when a custom network driver is used. Crafted packets can trigger memory corruption that permits remote code execution. The flaw is serious because it is network-reachable and requires no authentication.
Impact
A remote attacker can execute arbitrary code with full system privileges, leading to complete compromise of confidentiality, integrity and availability. No user interaction is needed beyond the target using a custom network driver.
Attack surface
Reachable over the network via crafted ESP-over-UDP packets (CVSS vector AV:N/AC:L/Au:N), so no authentication or user interaction is required. The vulnerable path is only exercised when a custom network driver is in use.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at 0.48764 (98.8th percentile), indicating elevated predicted exploitation likelihood. Reference tags are limited to a US-CERT alert and Microsoft bulletin, with no public exploit tag.
What to do
- Apply Microsoft security bulletin MS10-009 immediately on affected Windows Vista and Server 2008 systems.
- Remove or replace custom network drivers that are not required, since the flaw only manifests when a custom driver is used.
- Restrict network exposure of affected hosts and filter unexpected ESP-over-UDP traffic at the perimeter where feasible.
- Monitor vendor guidance and US-CERT TA10-040A for updated remediation steps.
- Retire or isolate unsupported Vista and Server 2008 Gold/SP1/SP2 systems that cannot be patched.
Detection
- Monitor for anomalous or malformed ESP-over-UDP traffic directed at Windows Vista or Server 2008 hosts.
- Alert on unexpected crashes or restarts of the TCP/IP stack or network drivers on affected systems.
- Audit hosts for the presence of custom network drivers that could expose the vulnerable fragmentation path.
- Correlate network IDS/IPS signatures for crafted ESP-over-UDP fragmentation with host-level crash or code-execution indicators.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-0240 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0240), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.